Skip to content

harden(janitor): SHA-pin actions/checkout (org-token-handling action) - #22

Closed
asachs01 wants to merge 2 commits into
mainfrom
fix/janitor-gap2-pin-checkout
Closed

harden(janitor): SHA-pin actions/checkout (org-token-handling action)#22
asachs01 wants to merge 2 commits into
mainfrom
fix/janitor-gap2-pin-checkout

Conversation

@asachs01

Copy link
Copy Markdown
Member

GAP-2 (warden-elevated): the janitor's checkout step persists the org-wide app-token into .git/config (backlog push). Floating @v4 → repointed-tag = org-token exfil = fleet compromise. SHA-pin to v4.3.0 per CI-QW-3. Pure pin, zero behavior change. Ready for Aaron approve + warden security-glance.

…pp-token)

GAP-2 (warden severity-elevated): the checkout step does token: ${{ steps.app-token.outputs.token }}
to push the backlog, persisting the ORG-WIDE Contents+PR app-token into .git/config. A
floating @v4 tag → a repointed/compromised tag could exfiltrate the crown-jewel token =
fleet-wide compromise. SHA-pin to v4.3.0 (34e114876b0b11c390a56381ad16ebd13914f8d5) per
CI-QW-3. Pure pin, zero behavior change. (create-github-app-token was already pinned.)
warden pin-legitimacy check: 34e114876b0b11c390a56381ad16ebd13914f8d5 is checkout
v4.3.1 (current v4 head), NOT v4.3.0 (=08eba0b). SHA is legitimate; the comment
mislabeled the version. SHA + comment must AGREE (the comment is how a human audits
the intended version). Corrected to v4.3.1 (latest v4 patch, fine to pin).
@asachs01

Copy link
Copy Markdown
Member Author

warden pin-legitimacy catch: 34e1148 = v4.3.1 (current v4 head), not v4.3.0 (=08eba0b). SHA is legit; comment was mislabeled → corrected to # v4.3.1. SHA+comment now agree.

@asachs01

Copy link
Copy Markdown
Member Author

Flagging from today's pr-sweep: this PR has a merge conflict with the base branch (mergeable=CONFLICTING) and hasn't been touched in a while. Rebase whenever it's still wanted — not urgent, just surfacing so it doesn't rot silently.

@asachs01

Copy link
Copy Markdown
Member Author

Closing as obsolete — the goal here is already met on main, at a newer version.

This PR changes actions/checkout@v4 → SHA-pinned 34e114876b0b11c390a56381ad16ebd13914f8d5 # v4.3.1. But main has since moved to:

uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3

landed via #24 (the Node 24 action bump). So the org-token-handling checkout step is SHA-pinned today, and merging this would downgrade it v6.0.3 → v4.3.1. The PR is also CONFLICTING/DIRTY against current main.

GAP-2 as described is resolved. Reopen if the pin regresses.

Verified against main 2026-08-17 while surveying janitor state for #51.

@asachs01 asachs01 closed this Aug 17, 2026
@github-project-automation github-project-automation Bot moved this from Todo to Done in MSP Claude Plugins Aug 17, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: Done

Development

Successfully merging this pull request may close these issues.

1 participant